Question:
HELP!!!! worm.win32.netsky has infected my computer what can I do?
neilyg
2010-01-04 07:18:18 UTC
Because of the virus I am unable to open my browsers and therefore unable to download AVG or any other applications that would remove the virus. Will not allow me to load any anti-spyware from the CD drive. What can I do to remove this virus.??
Five answers:
2010-01-04 07:33:17 UTC
Worm.Win32.Netsky Manual Removal Instructions



To remove Worm.Win32.Netsky, you must first stop any Worm.Win32.Netsky processes that are running in your computer's memory. To stop all Worm.Win32.Netsky processes, press CTRL+ALT+DELETE to open the Windows Task Manager. Click on the "Processes" tab, search for Worm.Win32.Netsky, then right-click it and select "End Process" key.



To delete Worm.Win32.Netsky registry keys, open the Windows Registry Editor by clicking on the Windows "Start" button and selecting "Run." Type "regedit" into the box and click "OK." Once the Registry Editor is open, search for the registry key "HKEY_LOCAL_MACHINE\Software\Worm.Win32.… Right-click this registry key and select "Delete."



Finally, to completely get rid of Worm.Win32.Netsky, you must manually remove other Worm.Win32.Netsky files. These Worm.Win32.Netsky files can be in the form of EXE, DLL, LSP, TOOLBAR, BROWSER HIJACK, and/or BROWSER PLUGIN. For example, Worm.Win32.Netsky might create a file like

%PROGRAM_FILES%\Worm.Win32.Netsky\Worm… Locate and remove these files.



http://malware-virus-spyware-remover-tools.blogspot.com/
ilknur K
2010-01-04 15:13:01 UTC
The Best way to Remove all kind of Virus,Trojans,Malware,Spyware,

Worm,Pop Up Advertisements ,Hijack Web browser rootkit and all Rogue Fake

Anti-virus in you Computer is Restart You Computer Safe Mode with Networking



1. Log out and reboot your machine.



2. When the machine starts the reboot sequence, press the F8 key repeatedly.



3. Select Safe Mode with Networking from the resulting menu.



4. Login. If the malware has changed your password, try logging in as

Administrator. By default, Administrator has no password.



5. The machine will continue booting, but the Windows desktop will look different.



Then in The Safe With Networking .Download and Scan By Using Malwarebytes’ Anti-Malware http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?tag=contentBody;mostPopTwoColWrap&cdlPid=10997763

Download and Scan By Using Super Anti-Spyware Press here http://www.superantispyware.com/



Download and Scan By using Norman Malware Cleaner Press here http://majorgeeks.com/downloadget.php?id=5450&file=1&evp=6980e63d4e482f0670e991265b3250e7



Download ATF is a new, freeware, temporary file cleaner for Windows, IE, Firefox and Opera with a simple, easy-to-use interface.



The main screen allows the user to either clean all temporary files, or select files for cleaning. The program also knows if Firefox and or Opera is being used, and gives the option of cleaning the temporary files associated with those applications.



ATF Cleaner provides the user with a window showing the total bytes freed upon completion. The program is small (36kb), quick to run and no installation required. to Download ATF Cleaner press this link http://majorgeeks.com/ATF_Cleaner_d4949.html



6. When you're finished Remove Virus, Malware, Trojan, Worm,

rogue

virus rootkit and

Spyware log out and reboot back into normal mode
2014-08-28 15:37:43 UTC
Don't listen to these guys, they clearly have no clue on what they're talking about. I am a developer at Microsoft so I know a thing or two about computers. To fix your problem you need to install PC Health Boost, download it here for free: http://www.pchealthcleaner.net



It's very light and it's the only antivirus/cleaner with a 99.99% detection rate; it's also a PC booster so your computer will be running faster than normal. Install it, hit run and problem solved. It shouldn't take you more than 5 minutes.
2010-01-04 07:31:12 UTC
Worm.Win32.Netsky is a parasite that has returned recently in the popup warning messages claiming that your system has been hijacked and infected with this dangerous Worm infection. This fake alert is generated by a Trojan program that creeps into the system bundled with Active-X plug-ins related to fake video codecs. Once executed, this Trojan will bombard the user with irritating pop-ups in the system tray, warning messages and may even slow down tour system performance. If you click on any of these notifications, you will be directed to the website where the rogue anti-spyware applications will be promoted and you will be tricked into buying one of them.



Well you can simply remove it…..

Just follow the instructions listed below……

Click "Start," "Control Panel" and "Add and Remove Programs." Click on "Worm.Win32.Netsky" and click "Remove."

Search for "Worm.Win32.Netsky" by clicking "Start," "Search" and "All Files or Folders." Write down the location of the folder containing the files as you will need this information later.

Delete the virus files by clicking "Start," "Run" and type "cmd," then click the "OK" button. Type the directory and folder name from Step 2. Example "C:\Program Files\Worm.Win32.Netsky." Delete the following files by typing "del filename." Example: "del Jammer2nd.exe." "PK_ZIP0.LOG," "PK_ZIP1.LOG," "PK_ZIP3.LOG," "PK_ZIP4.LOG," PK_ZIP5.LOG," "PK_ZIP6.LOG," "PK_ZIP7.LOG," "\Jammer2nd.exe," "\pk_zip_alg.log," "%windir%\PK_ZIP2.LOG," "%windir%\PK_ZIP8.LOG," "%windir%\PK_ZIP9.LOG," "%windir%\Jammer2nd.exe" and "%windir%\pk_zip_alg.log."

Edit the registry by clicking "Start," "Run" and type "regedit," then click the "OK" button. Search the registry values for "Jammer2nd" and delete.
2010-01-04 07:26:53 UTC
Boot into safemode with networking if possible (F7/F8 at startup)



run this file on it first:

http://download.bleepingcomputer.com/grinler/rkill.exe





Cant download? you may have to change name from rkill.exe to xxxxxx.exe ect

-USB







then go to download.com and install malwarebytes & Spybot Search & Destroy.

Update - Full scan - Fix Problem















Doesn't work? Insert livecd - click F12 at startup - boot from cd


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...